PT-2026-60293 · Zoom · Zoom Workplace+1

CVE-2026-53412

·

Published

2026-07-14

·

Updated

2026-08-12

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoom Workplace for Windows versions prior to 7.0.0 Zoom VDI Client for Windows versions prior to 7.0.10 Zoom VDI Client for Windows versions prior to 6.6.15 Zoom VDI Client for Windows versions prior to 6.5.18 Zoom Meeting SDK for Windows versions prior to 7.0.0
Description An improper input validation issue exists in the Windows desktop client, VDI client, and Meeting SDK. This flaw allows an unauthenticated remote attacker with network access to perform a full account takeover without requiring user credentials or interaction. Improper input validation occurs when a software application fails to properly verify or filter the data it receives, which can lead to unexpected behavior or security breaches.
Recommendations Update Zoom Workplace for Windows to version 7.0.0 or later. Update Zoom VDI Client for Windows to versions 7.0.10, 6.6.15, or 6.5.18 depending on the specific branch. Update Zoom Meeting SDK for Windows to version 7.0.0 or later. Enforce multi-factor authentication (MFA), single sign-on (SSO), and conditional access. Restrict local administrator rights to reduce the impact of potential privilege escalation. Monitor for suspicious account activity and unusual login patterns.

Fix

LPE

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10991
CVE-2026-53412

Affected Products

Zoom Workplace
Zoom